Vulnerability in Schema Engine AI – AI Schema Markup, Reviews & Rich Snippets for SEO — CVE-2026-97282
MediumSeverity
—Estimated exploit probability
10,000+ sitesInstalls
3.1.1Fixed in
What to do now
Update Schema Engine AI – AI Schema Markup, Reviews & Rich Snippets for SEO to 3.1.1 or later.
Affected versions
- Everything up to and including 3.1.0
Affected: Schema Engine AI – AI Schema Markup, Reviews & Rich Snippets for SEO (plugin, review-schema)
What the vulnerability is
The SchemaEngine AI – AI Schema Markup, Reviews & Rich Snippets for SEO plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.1.0. This is due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.